GREED Posted July 17, 2018 Posted July 17, 2018 Better than quoting Hear'say! What have Littlewoods got to do with it?
DrCheese Posted July 17, 2018 Posted July 17, 2018 So sounds like the ICO are investigating them anyway, regardless of their attempts to not take any blame for any data lost (I get why they said that but )
synaesthesia Posted July 17, 2018 Posted July 17, 2018 (edited) PR wise they'd have done well just to acknowledge the problem and make it clear they will cooperate with the ICO and fully support schools in every way possible to resolve this rather than passing the buck around. It doesn't absolve us of our responsibility; if there's a breach we must report it to the ICO but with Capita's cooperation with them, they would have a clear audit trail. Should a fine occur (unlikely), the school would no doubt be ultimately responsible for paying it but it'd take a judge on Capita's payroll to not side with the school when they sue Capita for that amount + expenses. The whole thing sort of feels like a test; however that may not necessarily be a bad thing for us as a whole. Check your procedures, remedy any faults, stronger for when it happens in future. Edited July 17, 2018 by synaesthesia
kennysarmy Posted July 17, 2018 Posted July 17, 2018 My Data Manager reports: While we do indeed use CTF imports for all student starters and leavers, I never import any contact data anyway because it makes our database messy. It is useful just in case it impacts other parts of the CTF import process though. Is that a big phew by me?
synaesthesia Posted July 17, 2018 Posted July 17, 2018 Quite likely but worth running the tool anyway. A member of staff is flagged up for us as they're a named contact. The address it thinks we should have is wrong.... the patch to "fix" those errors would actually cause more problems!
hiphopamus Posted July 17, 2018 Posted July 17, 2018 To be clear, there is not going to be a patch to fix this issue. The process is going to be finding the issues by using the Database Diagnostics check 99 (patch 24157), then manually working through the list fixing the issues found. On a sidenote you are likely to get issues created by user error, there a usually lots of duplicate contacts on schools systems anyway. 1
jenatddm Posted July 17, 2018 Posted July 17, 2018 To be clear, there is not going to be a patch to fix this issue. The process is going to be finding the issues by using the Database Diagnostics check 99 (patch 24157), then manually working through the list fixing the issues found. On a sidenote you are likely to get issues created by user error, there a usually lots of duplicate contacts on schools systems anyway. Hi, you mention finding and manually fixing the issues. What effect do you think this has on transfers of your pupil data incl name and address made to others, ie. school census (mid Jan 2018 and again in mid May) and entire end of year new school data transfers ? ie year 6 data sent to secondary school? Shocking if Capita knew months ago and didn't flag it.
David44 Posted July 17, 2018 Posted July 17, 2018 Where are people getting the patches from? Do you really have to log a call with Capita and request each one separately?
jinnantonnixx Posted July 17, 2018 Posted July 17, 2018 https://www.theregister.co.uk/2018/07/17/capita_strikes_again_software_bug_in_schools_contact_book_risks_huge_data_breach/
hiphopamus Posted July 17, 2018 Posted July 17, 2018 Where are people getting the patches from? Do you really have to log a call with Capita and request each one separately? The patches should be available via your SIMS support team..
hiphopamus Posted July 17, 2018 Posted July 17, 2018 The incorrect contact data could potentially have been transferred with the CTF. From speaking to a lot of our secondary schools (I'm not from Capita by the way!) they don't tend to trust contact information and don't tick to include contact information when importing. There is not going to be a neat and tidy fix for this, support teams like ourselves are just going to have to support schools as much as we can through the process.
djrscally Posted July 18, 2018 Posted July 18, 2018 (edited) Better than quoting Hear'say! I'm too young to get this, had to google it edit: or possibly slightly too old, hard to tell. Edited July 18, 2018 by djrscally 2
Banjo Posted July 18, 2018 Posted July 18, 2018 What we have done is import a new report they we have built into schools db's and have asked the admin to run it. It should highlight any suspicious records held in the system. These will then need to be manually checked to ensure that the contact information is correct by issuing a new contact details form for the parents to fill in. At least this way schools haven't got to send out 1000's of them and check them all manually. Remember, Crapita 'commented out' the majority of the contact matching code in Decemeber 2017. Any CTF imported into the system since then could have mixed up its contacts with exisiting contacts of students in the system. Patching removes the 'REM' it doesn't fix any damage that has already been done since 2017.
MrMat Posted July 18, 2018 Posted July 18, 2018 Run the script on all of our Schools. Sent emails to schools advising of their 'affected' pupils and the seriousness of the issue. Receive read receipts "Your email was deleted without being read" *sigh*
Jawloms Posted July 18, 2018 Posted July 18, 2018 Run the script on all of our Schools. Sent emails to schools advising of their 'affected' pupils and the seriousness of the issue. Receive read receipts "Your email was deleted without being read" *sigh* This used to occur if the email was read in a preview pane and then deleted having never been marked as read. They might have read it. Sounds like even if they have, they're not doing anything about it though!
StevieM Posted July 18, 2018 Posted July 18, 2018 I wonder how confident they are the V4 script will identify all issues... I believe our Data Manager has done some exports / lookups / comparisons and identified an issue not flagged by the script. @tech-man - Can you confirm whether or not your DM found issues that were caused by the bug but not detected by the V4/24157 diagnostic?
David44 Posted July 18, 2018 Posted July 18, 2018 The Capita website is useless. Why do they make you keep raising tickets for the simplest of things? I have asked for some documentation on installing Patch 24157 and I assume I will eventually receive it but why isn't it on their website? There must be hundreds if not thousands of schools raising the same tickets asking for the same patches. Why not just have them available to download with a page giving generic installation instructions?
Jawloms Posted July 18, 2018 Posted July 18, 2018 Capita is useless. FTFY I haven't raised a ticket about the patch, but that's because I've emailed them twice about it and had no response at all so I don't have a ticket! 1
David44 Posted July 18, 2018 Posted July 18, 2018 I have raised 4 tickets so far. I created them all using My Account and two have so far had a reply. Each one was along the lines of "Please send me X" and the reply, which I don't even think was automated, was "Please find attached X". With X being the two patches, the Powerpoint that probably is meant to be available but the link on their article is broken and some basic instructions which might also be available if I was prepared to waste my time using their search.Who does this ridiculous system benefit? It's not the school and I can't see what Capita get out of making it so hard either.
mjk Posted July 18, 2018 Posted July 18, 2018 Who does this ridiculous system benefit? It's not the school and I can't see what Capita get out of making it so hard either. There will be a middle manager, somewhere in Capita, who's bonus is dependant upon the amount of money the educational sector wastes on creating tickets.
CAM Posted July 18, 2018 Posted July 18, 2018 Support ran the script for me and found two potential issues which it turned out were nothing to do with the bug and down to duplicate admissions records. Coupled with the earlier manual check, I'm pretty sure we aren't affected and it turns out our admissions officer was not importing contacts anyway. The ban on importing contacts via CTF is remaining indefinitely though with the risk of bad records coming through from primary schools.
DODICT Posted July 18, 2018 Posted July 18, 2018 Anyone had the conversation with capita on whether they have fulfilled their contractual obligations when they have been aware of a significant risk to the customer and have failed to fully communicate the issue and the potential fallout ? They are aware of the issue and there are still schools that dont know ? That doesn't sound like a GDPR compliant behaviour from a contracted data processor to me ?
DrCheese Posted July 18, 2018 Posted July 18, 2018 So the patch found a few results for us, but as the data manager has been checking CTF's against papercopies for the past few years anyway, the data appears correct again what we have anyway? How do we flag it as "ok" ?
UNCL3LARRY Posted July 18, 2018 Posted July 18, 2018 So the patch found a few results for us, but as the data manager has been checking CTF's against papercopies for the past few years anyway, the data appears correct again what we have anyway? How do we flag it as "ok" ? Just ignore it, the script simply checks to see if everything looks okay, as far as I am aware there are no flags. we had an issue where it saw an "incorrect" address, and the proposed address was the exact same as the "incorrect one"
djrscally Posted July 18, 2018 Posted July 18, 2018 Anyone had the conversation with capita on whether they have fulfilled their contractual obligations when they have been aware of a significant risk to the customer and have failed to fully communicate the issue and the potential fallout ? They are aware of the issue and there are still schools that dont know ? That doesn't sound like a GDPR compliant behaviour from a contracted data processor to me ? Yeah particularly given they're supposed to be governed by the GDPR's minimum terms now; one of which is... ☐ the processor must assist the data controller in meeting its GDPR obligations in relation to the security of processing, the notification of personal data breaches and data protection impact assessments;
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now